Security at TurboCart AI
Your store data is valuable. We treat it that way. Here's how we keep it safe.
Encryption in Transit & At Rest
All data transmitted between your browser and our servers uses TLS 1.3. Data stored in our databases is encrypted at rest using AES-256.
Role-Based Access Control
Internal access to production data is strictly limited. Engineers follow the principle of least privilege and require approval for any data access.
Secure Infrastructure
TurboCart AI is hosted on enterprise-grade cloud infrastructure with automatic failover, DDoS protection, and continuous uptime monitoring.
Audit Logs
All significant actions within the platform — logins, data exports, setting changes — are logged with timestamps for traceability.
Regular Security Reviews
Our codebase undergoes regular internal security reviews. We use automated dependency scanning to detect and patch known vulnerabilities.
Authentication Security
Passwords are hashed using bcrypt. We support two-factor authentication and enforce secure session management with short-lived tokens.
Your Data, Your Rights
Data Isolation
Each merchant account is isolated. Your store data is never shared with or accessible by other accounts, even within the same plan tier.
Third-Party Integrations
Integrations with Shopify, WooCommerce, and others use OAuth or official API tokens scoped to only what's necessary. We never store marketplace passwords.
Data Retention
You can delete your account and data at any time. We process deletion requests within 30 days and provide a data export before deletion if requested.
No Data Selling
We do not sell, rent, or monetize your personal or store data. It is used solely to operate and improve the TurboCart AI platform.
Found a Security Issue?
We take security disclosures seriously. If you believe you've found a vulnerability in our platform, please email us directly — do not post it publicly.
security@turbocartai.xyz